Back

MEDIUM

CCID: Integer overflow, leading to array index error when processing crafted serial number of certain cards

Published Jan 18, 2011

Description

Signedness error in ccid_serial.c in libccid in the USB Chip/Smart Card Interface Devices (CCID) driver, as used in pcscd in PCSC-Lite 1.5.3 and possibly other products, allows physically proximate attackers to execute arbitrary code via a smart card with a crafted serial number that causes a negative value to be used in a memcpy operation, which triggers a buffer overflow. NOTE: some sources refer to this issue as an integer overflow.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 18, 2011
Updated Aug 7, 2024
Reserved Dec 9, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Dec 13, 2010